Privacy Policy

This Privacy Policy explains how Shipeedo ("we," "us," or "our"), collects, uses, discloses, and protects your personal data when you use our logistics software as a service (SaaS) and related services. By accessing or using our services, you consent to the practices described in this policy.

1. Information We Collect

1.1 Purposes of Collection

We collect and process your personal data for the following purposes:

  • To provide, maintain, and improve our logistics SaaS services.
  • To enable you to purchase, access, and use our software.
  • To communicate with you about your account, updates, and support.
  • To market our services (where lawful and with your consent where required).
  • To comply with legal obligations, including tax, accounting, and regulatory requirements.
  • To conduct analytics to enhance user experience and service performance.
  • To prevent fraud, abuse, or security incidents.

1.2 Types of Information Collected

We may collect the following categories of personal data:

A. Information You Provide Directly

  • Account Information: Name, email address, phone number, company name, job title, and payment details (e.g., credit card information, billing address).
  • User Content: Data you upload, input, or store in our software (e.g., shipment details, customer data, inventory information).
  • Communication Data: Emails, chat logs, support tickets, and other correspondence with our team.

B. Information Collected Automatically

  • Technical Data: IP address, browser type, device information, operating system, and unique device identifiers.
  • Usage Data: Pages visited, features used, session duration, and other interactions with our software.
  • Cookies and Similar Technologies: We use cookies, web beacons, and other tracking technologies to enhance functionality and analyze usage.

C. Information from Third Parties

  • Payment Processors: Stripe, PayPal, or other providers may share transaction data with us.
  • Integrations: Data from third-party logistics providers, APIs, or plugins connected to your account.
  • Publicly Available Data: Information from public sources (e.g., company websites, LinkedIn).

1.3 Legal Basis for Processing (GDPR)

We process your data based on one or more of the following legal grounds:

  • Contractual Necessity: To fulfill our obligations under our Terms of Service.
  • Consent: Where you have explicitly agreed (e.g., marketing communications).
  • Legitimate Interests: For fraud prevention, analytics, and service improvements (balanced against your rights).
  • Legal Compliance: To meet regulatory or legal requirements.

1.4 Special Categories of Data (Sensitive Information)

We do not knowingly collect sensitive personal data (e.g., health, racial, or biometric information) unless:

  • You explicitly consent.
  • It is necessary for compliance with employment or social security law.
  • It is required to protect your vital interests or those of another person.

2. Use and Disclosure of Information

2.1 How We Use Your Data

Your data is used only for the purposes outlined in Section 1.1, unless we obtain your consent for additional uses.

2.2 Disclosure to Third Parties

We may share your data with:

  • Service Providers: Hosting providers (e.g., AWS, Azure), payment processors, and analytics tools (e.g., Google Analytics) under strict confidentiality agreements.
  • Business Partners: Resellers, integrations, or affiliates only with your consent or as necessary to deliver services.
  • Legal Authorities: If required by law (e.g., court order, regulatory request).
  • Affiliates: Other entities under Shipeedo’s control, only for internal administrative purposes.

We do not sell your personal data.

2.3 International Data Transfers

  • Your data may be transferred to and processed in countries outside the EU/EEA where our servers or service providers are located.
  • We ensure such transfers comply with GDPR Chapter V by:
    • Using EU Standard Contractual Clauses (SCCs).
    • Relying on adequacy decisions (e.g., for UK, Canada).
    • Implementing binding corporate rules or other approved mechanisms.

3. Data Retention

We retain your data only for as long as necessary for the purposes described in this policy, or as required by law:

  • Account Data: Retained for the duration of your contract + 2 years for legal/tax purposes.
  • Payment Data: Retained for 7 years (or as required by local tax laws).
  • Usage/Analytics Data: Aggregated and anonymized where possible; raw data deleted after 26 months.

4. Data Security

We implement industry-standard technical and organizational measures to protect your data, including:

  • Encryption: TLS for data in transit; AES-256 for data at rest.
  • Access Controls: Role-based permissions and multi-factor authentication (MFA).
  • Regular Audits: Penetration testing and compliance reviews.
  • Incident Response: Prompt notification of any data breach affecting your rights (within 72 hours under GDPR).

5. Your Rights

5.1 Access and Control

You have the following rights under GDPR and other applicable laws:

  • Right to Access: Request a copy of your personal data.
  • Right to Rectification: Correct inaccurate or incomplete data.
  • Right to Erasure: Delete your data (subject to legal retention requirements).
  • Right to Restrict Processing: Limit how we use your data.
  • Right to Data Portability: Receive your data in a machine-readable format.
  • Right to Object: Opt out of direct marketing or processing based on legitimate interests.
  • Right to Withdraw Consent: Revoke consent for non-essential processing (e.g., marketing).

5.2 Automated Decision-Making

We do not use automated decision-making (including profiling) that produces legal effects or significantly affects you.

6. Cookies and Tracking Technologies

We use cookies to:

  • Enable core functionality (e.g., authentication).
  • Analyze usage (e.g., Google Analytics).
  • Personalize your experience.

Options:

  • Browser Settings: Disable cookies (may affect functionality).
  • Cookie Consent Tool: Manage preferences via our banner.

7. Third-Party Links

Our software may contain links to third-party websites (e.g., payment gateways, integrations). This policy does not apply to those sites. We encourage you to review their privacy practices.

8. Updates to This Policy

We may update this policy periodically. We will notify you of material changes via:

  • Email (to the address associated with your account).
  • A prominent notice on our website.

Continued use of our services after changes constitutes acceptance.